MEDIUM6.1
GHSA-px3r-jm9g-c8w8
rails-html-sanitizer Cross-site Scripting vulnerability
Quick fix
GHSA-px3r-jm9g-c8w8 — rails-html-sanitizer: upgrade to the fixed version with the command below.
bundle update rails-html-sanitizerDetails
There is a possible XSS vulnerability in all rails-html-sanitizer gem versions below 1.0.4 for Ruby. The gem allows non-whitelisted attributes to be present in sanitized output when input with specially-crafted HTML fragments, and these attributes can lead to an XSS attack on target applications. This issue is similar to CVE-2018-8048 in Loofah. All users running an affected release should either upgrade or use one of the workarounds immediately.
Are you affected?
Enter the version of the package you're using.